DeMomentSomTres Gift Ticket Security & Risk Analysis

wordpress.org/plugins/demomentsomtres-wc-cadeau

PDF Gift Cards for WooCommerce

0 active installs v202201120000 PHP + WP 5.0+ Updated Unknown
all-postsarchivescategory
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DeMomentSomTres Gift Ticket Safe to Use in 2026?

Generally Safe

Score 100/100

DeMomentSomTres Gift Ticket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the "demomentsomtres-wc-cadeau" plugin, version v202201120000, reveals a largely positive security posture concerning direct attack vectors and data handling. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and no unprotected entry points. Furthermore, there are no recorded dangerous functions, file operations, or external HTTP requests. All SQL queries utilize prepared statements, and there are no recorded vulnerabilities (CVEs) in its history. However, a significant concern arises from the complete lack of output escaping. With 100% of outputs unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website that could be executed by unsuspecting users.

The plugin's vulnerability history is clean, which is a positive indicator. The absence of known CVEs suggests that the developers have either been diligent in maintaining security or the plugin hasn't been a target of widespread vulnerability discovery. The taint analysis also shows no identified flows with unsanitized paths, further reinforcing the lack of direct exploitable data flows detected by this analysis. The presence of the 'dompdf' library, while not inherently a vulnerability, could become a risk if it's an outdated version with known security flaws; this is not explicitly stated in the provided data. In conclusion, while the plugin demonstrates strong practices in preventing direct access and protecting database interactions, the critical oversight in output escaping creates a significant security weakness that requires immediate attention.

Key Concerns

  • 0% of outputs properly escaped
  • Bundled library: dompdf
Vulnerabilities
None known

DeMomentSomTres Gift Ticket Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DeMomentSomTres Gift Ticket Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

dompdf

Output Escaping

0% escaped5 total outputs
Attack Surface

DeMomentSomTres Gift Ticket Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadeddms3-woocommerce-cadeau.php:25
actionplugins_loadeddms3-woocommerce-cadeau.php:59
actiontgmpa_registerdms3-woocommerce-cadeau.php:63
actioninitdms3-woocommerce-cadeau.php:67
filterrwmb_meta_boxesdms3-woocommerce-cadeau.php:71
actionwoocommerce_before_add_to_cart_buttondms3-woocommerce-cadeau.php:73
filterwoocommerce_add_cart_item_datadms3-woocommerce-cadeau.php:74
actionwoocommerce_checkout_create_order_line_itemdms3-woocommerce-cadeau.php:75
filterwoocommerce_cart_item_namedms3-woocommerce-cadeau.php:76
actionwoocommerce_before_order_itemmetadms3-woocommerce-cadeau.php:77
actionwoocommerce_order_item_meta_startdms3-woocommerce-cadeau.php:78
filterwoocommerce_loop_add_to_cart_linkdms3-woocommerce-cadeau.php:79
Maintenance & Trust

DeMomentSomTres Gift Ticket Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DeMomentSomTres Gift Ticket Developer Profile

Marc Queralt i Bassa

15 plugins · 340 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DeMomentSomTres Gift Ticket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/demomentsomtres-wc-cadeau/css/wccadeau.css/wp-content/plugins/demomentsomtres-wc-cadeau/js/wccadeau.js
Script Paths
/wp-content/plugins/demomentsomtres-wc-cadeau/js/wccadeau.js
Version Parameters
demomentsomtres-wc-cadeau/css/wccadeau.css?ver=demomentsomtres-wc-cadeau/js/wccadeau.js?ver=

HTML / DOM Fingerprints

CSS Classes
dms3-wccadeau
Data Attributes
data-dms3-wccadeau-recipient-namedata-dms3-wccadeau-guestsdata-dms3-wccadeau-validity
JS Globals
window.dms3_wccadeau_ajaxurlwindow.dms3_wccadeau_id_productwindow.dms3_wccadeau_recipient_namewindow.dms3_wccadeau_guestswindow.dms3_wccadeau_validity
FAQ

Frequently Asked Questions about DeMomentSomTres Gift Ticket